Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19B221F33A600DD298D9B96CCF6C09588811DC346FB3148CAB2A491BF7BC4DF0A99979D |
|
CONTENT
ssdeep
|
192:ES3JYdDKLPkKdag8aD6FMcnthWeNWbSILfMmUU8VCogi1:4DKdM3jILfMmUFCogi1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f0748f07871ba60f |
|
VISUAL
aHash
|
02c2c6c6040c08ff |
|
VISUAL
dHash
|
beb6b4bcbcf8f8d8 |
|
VISUAL
wHash
|
02c6cece0e0e0eff |
|
VISUAL
colorHash
|
01000000038 |
|
VISUAL
cropResistant
|
beb6b4bcbcf8f8d8,6a60eaf2b2c03373,fd9d9f9f9a7ef4fc,50b0a060c0800000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.